Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

3977 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.54%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+48/9/202617/9/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (5.5)0.54%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+48/9/202617/9/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AplazadaMedia (6.5)0.27%—Fastlinemedia Beaver BuilderAI8/9/20268/9/2026
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.10.3.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.…
AplazadaMedia (5.5)0.43%—Sourcecodester Online Voting SystemAI7/9/20268/9/2026
A weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument Category causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and…
AplazadaBaja (2.1)0.45%—Projectworlds Online Examination SystemAI7/9/20268/9/2026
A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedback Form. Executing a manipulation of the argument Name/Subject can lead to cross site scripting. The attack may be launched remotely. The exploit…
AplazadaBaja (2)0.33%—Projectwolds Online Attendance SystemAI6/9/20268/9/2026
A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The manipulation of the argument email results in cross site scripting. The attack may be performed from remote. The exploit has been released to the public…
AplazadaMedia (5.5)0.43%—Sourcecodester Online Voting SystemAI6/9/20268/9/2026
A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
AplazadaMedia (5.5)0.43%—Sourcecodester Online Voting SystemAI6/9/202611/9/2026
A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and…
AplazadaMedia (5.5)0.43%—Sourcecodester Online Voting SystemAI6/9/20268/9/2026
A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be…
AplazadaMedia (5.5)0.43%—Sourcecodester Online Voting SystemAI6/9/20268/9/2026
A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
AplazadaCrítica (9.8)0.50%—Lupsonline SEO FlowAI5/9/20268/9/2026
The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the…
AplazadaMedia (6.1)0.17%—Fastlinemedia Beaver BuilderAI5/9/20268/9/2026
The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all versions up to, and including, 2.11.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaBaja (2)0.35%—Code-projects Online Shopping SystemAI4/9/20268/9/2026
A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the argument mobile can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.
AplazadaMedia (6.3)0.18%—PIK Online Software Solutions INC PIK Online PortalAI4/9/20268/9/2026
Use of a One-Way hash without a salt vulnerability in Pik Online Software Solutions Inc. Pik Online Portal allows Cryptanalysis. This issue affects Pik Online Portal: through 3.5.1.
AplazadaMedia (5.5)0.50%—Itsourcecode Online Medicine Delivery SystemAI3/9/20264/9/2026
A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. The affected element is the function doInsert of the file /rider/orders/controller.php?action=add of the component Order Management Controller. Performing a manipulation of the argument image results in unrestricted upload. Remote…
AplazadaBaja (2)0.35%—Itsourcecode Online Medicine Delivery SystemAI3/9/20265/9/2026
A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the file /index.php?q=orderdetails. Such manipulation of the argument location leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.
AplazadaMedia (5.3)0.33%—Itsourcecode Online Medicine Delivery SystemAI3/9/202615/9/2026
A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=addwish of the component Wishlist. This manipulation of the argument proid causes sql injection. The attack may be initiated remotely.
AplazadaMedia (5.5)0.43%—Itsourcecode Online Medicine Delivery SystemAI3/9/20264/9/2026
A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function Order::pupdate of the file /rider/orders/controller.php?action=edit&actions=confirm of the component Order Status Update. The manipulation of the argument ID leads to sql injection. It…
AplazadaBaja (2.1)0.37%—Itsourcecode Online Medicine Delivery SystemAI3/9/20264/9/2026
A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/controller.php?action=photos of the component Customer Controller. Executing a manipulation of the argument photo can lead to unrestricted upload. The…
Pendiente de análisisMedia (5.4)0.14%—JenkinsAIJenkins Pipeline Groovy LibrariesAI2/9/20263/9/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc688825312 and earlier allows attackers to delete shared library caches.
Pendiente de análisisMedia (5.4)0.36%—Jenkins Pipeline Build StepAI2/9/20263/9/2026
A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds awaited by the `waitForBuild` step when the `propagateAbort` parameter is used to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job.
Pendiente de análisisMedia (5.4)0.36%—Jenkins Pipeline Build StepAIJenkins PipelineAI2/9/20263/9/2026
A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds triggered by the `build` step to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job.
AplazadaMedia (5.5)0.43%—Code-projects Online Shopping SystemAI31/8/20262/9/2026
A vulnerability was determined in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /action.php of the component Search Functionality. This manipulation of the argument keyword causes sql injection. It is possible to initiate the attack remotely. The exploit has…
AplazadaBaja (2.1)0.47%—Code-projects Online Shopping SystemAI31/8/202631/8/2026
A vulnerability was found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /offersmail.php of the component Newsletter Subscription. The manipulation of the argument email results in cross site scripting. The attack may be performed from remote. The…
AplazadaAlta (8.7)0.24%—Hulumi BaselineAI31/8/202631/8/2026
@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially evading audit trail monitoring.